Production Region ap-south-1 Host preskool-app-01 Uptime 46 days Build 4.8.2+2091

System Settings

Everything the platform runs on — services, performance, storage, maintenance, APIs and backups. Changes here reach every school on this installation, not one.

3 items need attention
Platform version4.8.2 4.9.0 available
EnvironmentProduction
System statusOperational · 9 of 10 services
ConfigurationPublished 2 drafts
Last update31 Jul 2026, 02:14
Disk412 GB of 500 GB used
Section 01

General

What the installation calls itself, and the defaults it hands down.

Identity

What the installation calls itself

Published
Application nameShown in the browser tab, on emails and on printed documents
Application URLEvery generated link is built from this
Admin URLA separate path keeps the console off the public site
Support contactPrinted on error pages
Installation IDFixed at install and used for licensing
PRSK-9F41-22A8
5 settings

Locale defaults

Inherited by every school on this installation

Inherited
TimezoneAsia/Kolkata · GMT +5:30
Default languageEnglish (India)
Date format31 Jul 2026
CurrencyIndian Rupee
A school may override theseLocalization settings are per school
5 settings · overridable

Sessions

How long a signed-in user stays signed in

30 min idle
Idle timeoutThen a re-prompt, not a sign-out
Absolute lifetimeWhatever the activity
Concurrent sessionsPer user account
Session driverRedis — survives an application restart
Remember meExtends a session to 30 days on a trusted device
5 settings

Who may change this

System settings are not a tenant permission

2 accounts
Permitted rolesSuper Administrator only — not school administrators
Platform role
Accounts holding itMs. Latha Rao and the break-glass account
2
Two-factor requiredTo save or publish anything on this page
Second approverMaintenance mode and restore need one
Every change recordedCannot be switched off
5 settings
Section 02

Application

Tenancy, feature flags and what the application will accept.

Tenancy

How many schools this installation serves

3 schools
ModeMulti-tenant — one database, scoped by school
SchoolsGlobal International, Sunrise Public, Riverside Academy
3
Users across all schoolsStaff, guardians and students
6,214
Cross-school accessOff — nobody sees another school’s records
New school onboardingManual, by a Super Administrator
5 settings

Feature flags

What is switched on for this installation

6 flags
AI moduleInsights, forecasts and the assistant
Parent portalGuardian sign-in and fee payment
Transport moduleRoutes, vehicles and tracking
Hostel moduleOnly one school uses it
Beta featuresOff in production, on in staging
Public API v2Not released — v1 remains the supported interface
6 flags · 4 on

Notification defaults

What a new school inherits

Configured
Email transportAmazon SES — set in email settings
Email settings
SMS gatewayMSG91 — set in SMS settings
SMS settings
Push notificationsNot configured — no mobile application yet
Not set
Platform noticesMaintenance and outage notices to all administrators
4 settings

Uploads

What the application will accept

25 MB
Maximum file sizePer file
Permitted typesDocuments, images and spreadsheets
pdf jpg png xlsx docx
ExecutablesRefused outright, whatever the extension says
Virus scan on uploadClamAV, before the file is stored
Image re-encodingStrips metadata, including location
5 settings
Section 03

Platform Services

Ten services and thirty days of history for each.

Ten services, each showing thirty days of history. The strip matters more than the percentage — four consecutive red days is a different problem from four scattered ones.

Application

preskool-app-01 · php-fpm 8.3

Running 4.8.2
30 days100% uptime
Restarted 46 days ago

Database

MySQL 8.0.36 · primary

Running 8.0.36
30 days100% uptime
Restarted 46 days ago

Scheduler

cron · every minute

Running
30 days100% uptime
Restarted 46 days ago

Queue worker

4 workers · redis driver

Degraded
30 days99.4% uptime
Restarted 2 hours ago

Email service

Amazon SES · ap-south-1

Running v2
30 days100% uptime
Restarted 11 Jun 2026

SMS service

MSG91 · transactional

Running v5
30 days99.9% uptime
Restarted 14 Jan 2026

Object storage

S3 · preskool-media

Running
30 days100% uptime
Restarted 46 days ago

Search service

Meilisearch · 12 indexes

Running 1.8.0
30 days99.7% uptime
Restarted 9 days ago

API service

REST v1 · 4 consumers

Running v1
30 days100% uptime
Restarted 46 days ago

AI services

Inference endpoint · batch nightly

Stopped 2.1.0
30 days73.2% uptime
Restarted 4 days ago
Section 04

Performance

Where the time goes, and what is given up under load.

Delivery

What reaches the browser, and how much of it

Optimised
CompressionBrotli, falling back to gzip
Asset bundlingMinified and fingerprinted at build
Lazy loadingImages below the fold load when scrolled to
Image optimisationWebP with a JPEG fallback, resized on upload
CDNNot in use — a single region serves all three schools
5 settings

Database

Where most of the time actually goes

Tuned
Query cacheRead queries cached for 60 seconds
Slow query logAnything over 500ms is recorded
Connection poolMaximum simultaneous connections
Index maintenanceRebuilt weekly during the maintenance window
Read replicaNot configured — load does not warrant one yet
5 settings

Current load

Measured over the last hour

Disk high
CPU · 4 cores34%
Memory · 16 GB9.8 GB
Disk · 500 GB412 GB
Queue depth214 jobs
Average response186 ms

Disk is the only figure worth acting on. Everything else has comfortable headroom at the busiest hour of the school day.

Sampled every 60 seconds

Performance mode

What the platform gives up when it is busy

Balanced
ModeBalanced — the default
Under load, deferReport generation and AI batch work
Under load, never deferSign-in, fee payment and attendance
Request timeoutA request longer than this is abandoned
Rate limit per userRequests per minute
5 settings
Section 05

Storage

412 GB of 500 GB, and what is on it.

Volume · /var/preskool

412 GB of 500 GB used · 88 GB free

82% — alert at 85%
128 GB 94 GB 62 GB 82 GB 88 GB
Application 46 GB Media 128 GB Database 94 GB Logs 62 GB Backups 82 GB Free 88 GB

Logs are the fastest-growing partition and the easiest to reclaim. Reducing log retention from 90 days to 30 would return roughly 40 GB and cost nothing that is looked at.

Measured 31 Jul 2026, 02:14

Storage locations

Where each kind of file lives

2 drivers
MediaS3 · preskool-media · ap-south-1
DocumentsS3, with server-side encryption
LogsLocal disk — never leaves the host
BackupsS3 in a second region
Temporary filesLocal, cleared nightly
5 settings

Retention

What is kept, and for how long

1 too long
Application logs90 days — the largest reclaimable item
Audit logs3 academic years — required, not negotiable
Temporary uploadsCleared after 24 hours
Deleted recordsHeld 30 days in a recycle bin, then purged
Old backupsHandled by the backup retention policy
Backups
5 settings
Section 06

Cache

What is held in memory, and what clearing it costs.

Cache configuration

What is held in memory and for how long

Redis
DriverRedis — shared across application instances
Default lifetimeSeconds, unless a store overrides it
Configuration cacheCompiled at deploy, never at runtime
Route and view cacheCompiled at deploy
Cache on writeA record is cached the moment it is saved
5 settings

Clearing the cache

What it costs to do it

Use sparingly

Clearing everything at once forces every subsequent request to rebuild from the database. On a school-day morning that is felt immediately by everyone signing in.

Clear one store at a timeEach store below can be cleared on its own.
Prefer the maintenance window02:00 to 04:00, when fewer than five people are signed in.
Last full clear 14 Jun 2026
Cache stores
Configuration1.2 MB Compiled settings · rebuilt at deploy only
100% hit rate Warm
Routes and views8.4 MB Compiled templates · rebuilt at deploy only
100% hit rate Warm
Query results412 MB Read queries · 60 second lifetime
94% hit rate Warm
Sessions86 MB 1,284 active sessions
— hit rate Live
Report data1.8 GB Generated reports · 24 hour lifetime
61% hit rate Cold
AI inference0 MB Empty — the AI service is stopped
— hit rate Empty
Section 07

Background Jobs

What runs on its own, and what is failing.

Queue workers

What actually runs the jobs

3 of 4
WorkersThree of four are responding
3 / 4
DriverRedis
Queue depth214 jobs waiting, draining normally
214
Failed jobsAll from the AI batch
4
Restart workersRolling, so nothing in flight is lost
Worker 4 stopped responding at 00:12

Failure handling

What happens to a job that does not finish

3 attempts
AttemptsThen the job is moved to the failed table
Backoff1 min, 5 min, 30 min
TimeoutA job running longer than this is killed
Notify on failureThe IT administrator, once per job type per hour
Retain failed jobsFor inspection before they are discarded
5 settings
Scheduled jobs
Send queued emailevery minute Last run 2 sec ago · 18,204 today
Healthy
Send queued SMSevery minute Last run 2 sec ago · 4,182 today
Healthy
Generate report cardson demand Last run 4 hours ago · 96 this term
Healthy
Nightly database backup02:00 daily Last run 10 hours ago · 30 kept
Healthy
Reconcile bank settlements06:30 daily Last run 19 hours ago · 2 unmatched
Attention
Purge temporary files03:00 daily Last run 11 hours ago · 1.2 GB freed
Healthy
Rebuild search indexes03:30 weekly Last run 4 days ago · 12 indexes
Healthy
AI nightly batch01:00 daily Last run failed 4 days ago · —
Failing
Section 08

Maintenance

Taking the platform away, and putting it back.

Maintenance mode is off — the platform is open

Turning it on signs everyone out and shows a holding page to all 6,214 users across three schools. Only allow-listed addresses keep access. This is not reversible from a phone, so it is worth being at a desk.

Scheduled maintenance

When the platform expects to be interrupted

Nightly window
WindowFewer than five users are signed in at this hour
Automatic tasks in the windowBackup, index rebuild, cleanup and optimisation
Next planned outageFor the 4.9.0 upgrade
16 Aug 2026, 02:00
Notice periodAdministrators are told this far ahead
Notify guardiansOff — a nightly window nobody notices needs no notice
5 settings

Debug & error reporting

What the platform says when it goes wrong

Safe
Debug modeOff — a stack trace on a public page leaks paths and queries
Error detail shown to usersA reference number only
Error reporting serviceSentry · ap-south-1
Scrub personal data from reportsNames, emails and numbers removed before sending
Notify on a new error typeOnce per type per hour, not per occurrence
5 settings

Cleanup & optimisation

Housekeeping that runs on its own

Nightly
Temporary file purgeDaily at 03:00 · freed 1.2 GB last night
Orphaned mediaFiles with no record pointing at them
Expired sessionsCleared hourly
Table optimisationWeekly, in the maintenance window
Recycle bin purgeRecords deleted more than 30 days ago
5 tasks · all automatic

Manual actions

Things a Super Administrator can trigger now

Use carefully
Clear a cache storeSafe at any time; a store rebuilds itself on the next request.
Rebuild search indexesTakes about four minutes, during which search returns partial results.
Restart the queue workersRolling, so nothing in flight is lost, but scheduled jobs pause briefly.
Restore a configuration backupReplaces every setting on this page. Needs a second approver.
4 actions
Section 09

Security

Transport, access, secrets and what checks itself.

Transport & headers

What the browser is told to enforce

Enforced
HTTPS onlyA plaintext request is redirected, then refused
HSTSTwo years, including subdomains
Content security policyNo inline script, no external origins
Clickjacking protectionThe application may not be framed
TLS minimumTLS 1.2
5 settings

Access control

Who may reach the platform at all

Open with limits
IP allow-list for the consoleSchool network and two administrator addresses
Banned addressesAdded automatically after repeated failures
18
Rate limitRequests per minute per address
Failed sign-in lockoutFive attempts, then fifteen minutes
Break-glass accountOne, with an offline credential and full audit
1
5 settings

Secrets & encryption

How the platform keeps what it holds

AES-256
Encryption at restDatabase volume and object storage
Application keyRotated at install only — rotating it re-encrypts everything
••••••9F41
Secrets storeEnvironment file, outside the web root
Secrets in logsRedacted before anything is written
Backup encryptionSeparate key from the application key
5 settings

Scanning

What checks itself, and when

Clean
Dependency scan — no known vulnerabilitiesRan 31 Jul against 214 packages.
File integrity — nothing modified outside a deployChecked hourly against the deployed manifest.
Upload scanning — 8,412 files scanned this monthTwo rejected, both mislabelled executables.
Penetration test is 14 months oldPolicy asks for one a year. The last report closed with no high findings.
Last full scan 31 Jul 2026, 02:40
Section 10

Logging

What is written, kept and alerted on.

Log configuration

What is written, and where

info and above
LevelDebug is written in staging only
ChannelsDaily file, plus errors to Sentry
RotationOne file a day
RetentionNinety days — the largest reclaimable partition
Personal dataNames and identifiers redacted before writing
5 settings

Log alerts

What raises a notice rather than a line

2 firing
Any error level entryTo the IT administrator
Repeated identical errorGrouped — one notice per type per hour
Disk above thresholdCurrently firing at 82%
Service downFiring for the AI service since 27 Jul
Quiet hoursNone — a platform alert at 03:00 is the point
5 settings

Recent platform log

Last 10 of 214,908 entries · retained 90 days

6 info 3 warn 2 error
2026-07-31 02:14:02 info configuration published by latha.rao · 4 settings changed
2026-07-31 02:04:11 info nightly backup completed · 2.4 GB · 6 min 12 s
2026-07-31 03:00:00 info temporary file purge freed 1.2 GB
2026-07-31 06:31:40 warn bank reconciliation: 2 entries unmatched · queued for review
2026-07-27 01:00:14 error ai.batch.nightly failed · inference endpoint refused connection
2026-07-27 01:05:14 error ai.batch.nightly failed · attempt 2 of 3
2026-07-31 00:12:08 warn queue worker 4 stopped responding · jobs redistributed
2026-07-15 02:00:00 info search indexes rebuilt · 12 indexes · 3 min 48 s
2026-07-31 02:14:00 warn disk usage 82% · alert threshold is 85%
2026-06-15 09:20:31 info platform upgraded 4.8.1 to 4.8.2 · 4 min downtime
Times are Asia/Kolkata · logs are written in UTC
Section 11

API Services

How the platform is reached from outside.

REST API

How the platform is reached from outside

v1 live
EnabledFour consumers are using it
Base URLhttps://preskool.edu/api/v1
AuthenticationBearer token, scoped per key
Rate limitRequests per minute per key
VersioningA version is supported for 18 months after the next one ships
v1
5 settings

API keys

Who is holding one

1 overdue
Reporting integrationRead-only · 214 days old
Rotate
Accounting exportRead-only · 46 days old
Current
Mobile applicationRead and write · 90 days old
Current
Rotation policyEvery 180 days
Revoked keysKept in the audit record, never reissued
3
4 active keys
Endpoints
GET/api/v1/students Read student records · scoped by school
4 consumers Live
GET/api/v1/attendance Daily attendance · read only
2 consumers Live
POST/api/v1/fees/payment Record an offline payment
1 consumer Live
GET/api/v1/reports/summary Aggregate figures · no personal data
3 consumers Live
POST/hooks/payment/callback Gateway settlement callback · signed
MSG91, Razorpay Live
POST/hooks/sms/dlr SMS delivery receipts · signed
MSG91 Live
GET/api/v2/* Not released — v1 remains supported
None Disabled
Section 12

Integrations

What the platform talks to, and what may call in.

Connected services

What the platform talks to

1 stopped
Amazon SESOutbound email · ap-south-1
Connected
MSG91Outbound SMS · transactional route
Connected
RazorpayFee collection · production keys
Connected
MeilisearchSearch · self-hosted
Connected
AI inference endpointStopped since 27 Jul
Stopped
SentryError reporting
Connected
6 services · 5 connected

Webhooks

What is allowed to call in

Signed
Incoming endpointsPayment settlement and SMS delivery receipts
2
Signature verificationHMAC SHA-256 — unsigned calls are discarded
Replay protectionA signature is accepted once, within five minutes
Source allow-listOnly the provider’s published ranges
Failures in 30 daysAll were unsigned probes from the open internet
41
5 settings
Third-party applications

No third-party application has been authorised

Every integration in use is a first-party one the school configured directly — a payment gateway, a mail provider, an SMS route. Nothing external holds a token that acts on a user’s behalf, and until one does this list stays empty.

Section 13

Environment

What the platform is actually running on.

Runtime

What the platform is actually running on

Supported
preskool@app-01:~$ php artisan about

Environment ....... production
PHP ............... 8.3.9
Laravel ........... 11.14.0
Database .......... mysql 8.0.36
Cache ............. redis 7.2.4
Queue ............. redis
Session ........... redis
Storage ........... s3 (ap-south-1)
Debug ............. false
Maintenance ....... false

Every line here comes from the environment file, which sits outside the web root and is never included in an export or a backup of settings.

Read at 02:14 today

Environments

Three, and what each is for

3
Productionpreskool.edu · 6,214 users
Live
Stagingstaging.preskool.edu · a copy refreshed weekly
Non-live
LocalDeveloper machines · seeded data only
Off-platform
Promotion pathLocal, then staging, then production — never directly
Production data in stagingOff — staging uses anonymised records
5 settings

Infrastructure

The machines underneath

ap-south-1
Application hostpreskool-app-01 · 4 vCPU, 16 GB
Database hostpreskool-db-01 · managed, daily snapshot
Cache hostpreskool-cache-01 · Redis 7.2
Object storageS3 · preskool-media · versioned
Regionap-south-1 · Mumbai
Single region · no failover configured
Section 14

System Health

Eleven checks, every sixty seconds.

Health checks

Run every 60 seconds · 9 of 11 passing

2 failing
Application responds186 ms average over the last hour.
Database reachable12 ms, 14 of 40 connections in use.
Cache reachableRedis 7.2.4, 512 MB of 2 GB used.
Object storage writableTest object written and removed.
Scheduler ran in the last two minutesLast tick 41 seconds ago.
Queue workersThree of four responding. Worker 4 stopped at 00:12.
Mail transport acceptsSES returned 250 on a balance probe.
SMS gateway acceptsMSG91 returned 200 with a credit balance.
AI inference endpointConnection refused since 27 Jul. Nightly batch has not run in four days.
TLS certificate validExpires 14 Nov 2026, renewal automatic at 30 days.
Backup ran in the last 24 hoursCompleted 02:04 today, 2.4 GB.
Last run 47 seconds ago

Availability

What the last thirty days looked like

99.94%
01 Jul30 Jul

One interruption, on 22 July, when the search service restarted after an index rebuild ran out of memory. Four minutes, outside school hours, nobody signed in.

1 incident in 30 days

Alerting

Who is told, and when

2 recipients
Service downImmediately, to the IT administrator
Health check failingAfter two consecutive failures, not the first
Disk above 85%Currently at 82%, so not yet firing
Certificate expiringThirty days ahead
ChannelEmail and SMS — a platform alert should reach a phone
5 settings
Section 15

Backups

What is kept, and whether it has ever been restored.

Backup schedule

What runs, and where it lands

Nightly
Automatic backupEvery night at 02:00
ContentsDatabase, uploaded files and configuration
DestinationS3 in a second region, so a regional failure is survivable
EncryptionA key separate from the application key
Verify after writingThe archive is opened and checked, not just written
5 settings

Retention & restore

How far back you can actually go

Never tested
Daily backups keptRolling
Weekly archives keptOne a week
Yearly archivesKept indefinitely
Restore targetStaging first, always — never straight to production
Last restore drillNever run — a backup nobody has restored is a hope, not a backup
Never
The restore drill is the single largest gap here
Recent backups
31 Jul 2026, 02:04Full 2.4 GB · took 6 min 12 s · stored in ap-southeast-1
Verified
30 Jul 2026, 02:04Full 2.4 GB · took 6 min 04 s · stored in ap-southeast-1
Verified
29 Jul 2026, 02:04Full 2.3 GB · took 5 min 58 s · stored in ap-southeast-1
Verified
28 Jul 2026, 02:04Full 2.3 GB · took 6 min 21 s · stored in ap-southeast-1
Verified
27 Jul 2026, 02:04Full 2.3 GB · took 9 min 44 s · stored in ap-southeast-1
Slow
24 Jul 2026, 02:04Weekly archive 2.2 GB · took 6 min 02 s · stored in ap-southeast-1
Verified · kept 1 year
Section 16

Updates

4.9.0 is available and has been on staging for a week.

Version 4.9.0 is available

Released 22 Jul 2026 · currently running 4.8.2

Minor release

A minor release, so no database migration is destructive and the upgrade is reversible for seven days. It has been running on staging since 24 July without incident.

No breaking API changesv1 endpoints are unchanged.
Runs on the current PHP and database versionsNo host change needed.
Tested on staging for 7 daysRefreshed from a production copy on 24 July.
Estimated 4 minutes of downtimeScheduled for the maintenance window on 16 Aug.
Planned for 16 Aug 2026, 02:00

Update policy

What the platform may do on its own

Manual
Automatic updatesOff — a school ERP does not update itself mid-term
Security patchesApplied within 72 hours, in the maintenance window
Update channelStable
Notify on releaseTo the IT administrator
Rollback windowSeven days after a minor release
5 settings

Version history

What has been installed here

4 releases
4.8.2Installed 15 Jun 2026 · 4 min downtime
Current
4.8.1Installed 02 Apr 2026 · 6 min downtime
4.8.0Installed 14 Jan 2026 · 22 min downtime
4.7.4Installed 08 Sep 2025 · first install
Install
Installed 08 Sep 2025
Section 17

Licensing

What this installation is entitled to, and for how long.

Licence

What this installation is entitled to

Valid
Licence keyBound to the installation ID
PRSK-••••-22A8
TypeExtended · multi-school
Schools permittedThree of five used
3 / 5
Users permittedUnlimited on this tier
Unlimited
Valid untilPerpetual — support renews separately
Perpetual
5 settings

Support & updates

What runs out, and when

Expires in 68 days
Support planBusiness · 8 hour response
Update entitlementUntil 08 Oct 2026
68 days
After expiryThe platform keeps working; new versions stop arriving
RenewalHandled by the trust office, not from here
Off-platform
Remind before expiryDays ahead
Renewal not yet raised with the trust office
Section 18

Advanced

Environment variables, experimental flags and the reset switch.

APP_ENV=production
APP_DEBUG=false
APP_URL=https://preskool.edu
DB_CONNECTION=mysql
CACHE_STORE=redis
QUEUE_CONNECTION=redis
SESSION_DRIVER=redis
FILESYSTEM_DISK=s3
APP_KEY=∗∗∗∗∗∗∗∗∗∗∗∗∗∗∗∗
DB_PASSWORD=∗∗∗∗∗∗∗∗∗∗∗∗∗∗∗∗

Shown here for reference only. Secrets are masked and the file itself is edited on the host, never through the browser — a settings page that can rewrite its own credentials is a settings page that can lock you out.

New timetable engineOn in staging since June, no issues logged
Streaming report generationWould remove the wait on large report runs
Read replica routingRequires a replica, which is not provisioned
API v2Not released

Commands a Super Administrator may run from here rather than over SSH. Each is recorded in the audit history with the account that ran it.

php artisan cache:clear
php artisan queue:restart
php artisan scout:reindex
php artisan backup:run
php artisan schedule:list

Anything destructive — migrations, seeding, key rotation — is deliberately not available here.

Resetting returns every setting on this page to the shipped default. Data, schools, users and backups are untouched, but the platform will need reconfiguring before it behaves as it does now.

Section 19

Audit History

Every change, with the account against it.

Audit history

Every platform change and every automatic event, retained 3 years

8 of 1,842 entries
31 Jul 202602:14
Configuration published · 4 settingslatha.rao · from 103.21.58.14
31 Jul 202600:12
Queue worker 4 stopped respondingSystem · jobs redistributed automatically
27 Jul 202601:00
AI inference endpoint became unreachableSystem · nightly batch has not run since
22 Jul 202603:41
Search service restarted after an out-of-memory failureSystem · 4 minutes unavailable
15 Jun 202609:20
Platform upgraded 4.8.1 to 4.8.2latha.rao · 4 minutes of planned downtime
02 Jun 202614:02
Log retention raised from 30 to 90 daysr.venkatesh · the origin of the current disk pressure
14 Apr 202611:30
Backup destination moved to a second regionlatha.rao · ap-southeast-1
08 Sep 202510:00
Platform installedr.venkatesh · version 4.7.4
Entries cannot be edited or removed, including by a Super Administrator

System activity

How this installation reached its present state.

Platform installed

Version 4.7.4 on a single host in ap-south-1, with one school and 1,240 users.

Configuration updated

Log retention raised from 30 to 90 days. This is where the current disk pressure begins.

Maintenance enabled

Four minutes of planned downtime for the 4.8.2 upgrade, taken in the nightly window.

Backup completed

2.4 GB written to a second region and verified by opening the archive, not merely by writing it.

System optimised

Temporary files purged, expired sessions cleared and tables optimised. 1.2 GB reclaimed.

Configuration published

Four settings published, two more still held as drafts. The drafts are not in effect anywhere.

Recommendations

What the platform suggests looking at, in the order it would look.

Availability

Bring the AI service back or switch the module off

The inference endpoint has refused connections since 27 July and the nightly batch has not run in four days. Insights shown to teachers are now four days stale without saying so, which is worse than showing nothing.

Act now
Backups

Run a restore drill

Thirty daily backups exist and every one verified on write. None has ever been restored. A backup nobody has restored is a hope rather than a backup, and staging exists precisely so this can be tested without risk.

Act now
Storage

Reduce log retention to 30 days

Disk is at 82% against an 85% alert. Logs hold 62 GB and were raised from 30 to 90 days in June for a specific investigation that has since closed. Reverting it returns roughly 40 GB immediately.

Soon
Jobs

Restart queue worker 4

It stopped responding at 00:12 and the other three have absorbed its work, so nothing is queued behind it. It will not recover on its own, and three workers is thinner cover than intended.

Soon
Updates

Take 4.9.0 in the August window

It has run on staging for a week without incident, needs four minutes of downtime and is reversible for seven days. Waiting past the term start makes the same upgrade harder to schedule.

Soon
Security

Backups are encrypted with a separate key

Worth keeping. If the application key were ever exposed, the backups would not open with it. Several installations get this wrong by reusing one key for both.

Keep
Note

Two settings are still drafts

Neither is in effect. Publishing applies both at once and notifies every administrator, which is why they are usually left to accumulate until there is a reason to publish.

Note

Storage — /var/preskool

412 GB of 500 GB used · measured 31 Jul 2026, 02:14

82%

Configuration details

Mount point
/var/preskool
Device
/dev/nvme1n1
File system
ext4
Capacity
500 GB
Used
412 GB
Growth rate
~1.4 GB per day
Current values
Alert thresholdA notice is raised above this
Log retentionThe largest reclaimable item
Temporary file lifetimeHours
Automatic cleanupRuns nightly at 03:00
Automatic expansionNot available on a fixed volume
What is on the volume
128 GB 94 GB 62 GB 82 GB 88 GB
Application 46 GB Media 128 GB Database 94 GB Logs 62 GB Backups 82 GB Free 88 GB
Validation
Volume is writableTest file written and removed at 02:14.
Backups are on a different volumeAnd in a different region, so a disk failure does not take both.
82% used, alert threshold 85%Growing at roughly 1.4 GB a day, most of it logs.
No automatic expansionThe volume is fixed. At the current rate the threshold is reached in about eleven days.
System impact

Reducing log retention to 30 days returns roughly 40 GB and takes the volume to 74%.

No downtimeOld files are removed by the nightly cleanup, not by a restart.
Audit logs are unaffectedThey are retained for three years under a separate rule.
Loses application logs older than 30 daysOnly relevant to an investigation that goes back further than a month.
Dependencies
Backups Logging Object storage Nightly cleanup

If this volume fills, uploads fail first and the nightly backup fails second. Neither is announced to a user; both appear only in the log.

Related settings
Retention Upload limits Disk alerts Cleanup tasks
Audit history
31 Jul 202602:14
Usage measured at 82%System · nightly
02 Jun 202614:02
Log retention raised 30 to 90 daysr.venkatesh
14 Apr 202611:30
Backups moved off this volumelatha.rao · ap-southeast-1
08 Sep 202510:00
Volume provisioned at 500 GBr.venkatesh · at install